Pichard_Rarker
Posts: 47 +0
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.10.25.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
BigRigSniX :: BIGRIGSNIX-PC [administrator]
Protection: Enabled
10/25/2013 3:51:23 PM
mbam-log-2013-10-25 (15-51-23).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 224965
Time elapsed: 2 minute(s), 11 second(s)
Memory Processes Detected: 2
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (PUP.Optional.Conduit.A) -> 2052 -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\cltmng.exe (PUP.Optional.Conduit.A) -> 3240 -> Delete on reboot.
Memory Modules Detected: 3
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\ChromeModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
Registry Keys Detected: 5
HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\SEARCHPROTECT (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IECT3289663 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
Registry Values Detected: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SearchProtect (PUP.Optional.Conduit.A) -> Data: C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\cltmng.exe -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SearchProtectAll (PUP.Optional.Conduit.A) -> Data: C:\Program Files (x86)\SearchProtect\bin\cltmng.exe -> Quarantined and deleted successfully.
HKCU\Software\SearchProtect|IELastInstalledTBHomepage (PUP.Optional.SearchProtect.A) -> Data: http://search.conduit.com?SearchSource=10&CUI=UN39219230022248310&UM=2&ctid=CT3289663 -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit.A) -> Bad: (http://search.conduit.com/?ctid=CT3...M=2&UP=SP2FE50E72-DFCD-46F2-A4E1-56A3C2564727) Good: (http://www.google.com) -> Quarantined and repaired successfully.
Folders Detected: 28
C:\Program Files (x86)\SearchProtect\bin (PUP.Optional.SearchProtect.A) -> Delete on reboot.
C:\Program Files (x86)\SearchProtect\Dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\ffprotect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi\defaults (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi\defaults\preferences (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE\CT3289663 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
Files Detected: 112
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\cltmng.exe (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\ChromeModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Program Files (x86)\SearchProtect\bin\cltmng.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\SPHook32.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\SPHook64.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\SPRunner.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\SPTool64.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\air4F27.exe (PUP.Optional.SevereWeatherAlerts) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\BTXHcyOu.exe.part (PUP.Optional.InstallCore) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\nsl3B4C.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\nsq435A.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\nsw2724.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\nswED3D.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\WfATYKZ7.exe.part (PUP.Optional.AirInstaller) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\ctbe.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\ffLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\ieLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\spff.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\statisticsStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\stub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Downloads\Setup(1).exe (PUP.Optional.AirInstaller) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Conduit\CT3289663\InternetHelper3.1AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\D7XD0ZI1\internethelper3.1[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\D7XD0ZI1\InternetHelper3.1[2].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\LNG6CX1D\checktbexist[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\LUYRM7IH\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\LUYRM7IH\stublogic[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\LUYRM7IH\swa1_23[1].exe (PUP.Optional.SevereWeatherAlerts) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\WIC72A6Y\statisticsstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\FirefoxModule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\ChromeModule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\InternetExplorerModule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\SPHook32.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\SPHook64.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\SPRunner.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\SPTool64.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\uninstall.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\dialogsApi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\ffprotect\nsprotector.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\ffprotect\abstraction.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\ffprotect\application.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\dialogsApi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\nsprotector.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\abstraction.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\application.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\popupTransparent.xul (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\dialogsApi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository\EN (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository\searchProtectorData (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\chromeid.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\conduit.xml (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\CT3289663.xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\setup.ini.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\version.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi\install.rdf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi\defaults\preferences\defaults.js (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE\CT3289663\configutaion.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE\CT3289663\SetupIcon.ico (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE\CT3289663\UninstallerUI.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16720 BrowserJavaVersion: 10.40.2
Run by BigRigSniX at 16:00:28 on 2013-10-25
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.16345.14174 [GMT -7:00]
.
AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2014\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Users\BigRigSniX\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uURLSearchHooks: InternetHelper3.1 Toolbar: {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files (x86)\InternetHelper3.1\prxtbInte.dll
mURLSearchHooks: InternetHelper3.1 Toolbar: {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files (x86)\InternetHelper3.1\prxtbInte.dll
mWinlogon: Userinit = userinit.exe,
BHO: InternetHelper3.1 Toolbar: {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files (x86)\InternetHelper3.1\prxtbInte.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: InternetHelper3.1 Toolbar: {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files (x86)\InternetHelper3.1\prxtbInte.dll
uRun: [Spotify Web Helper] "C:\Users\BigRigSniX\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [BackgroundContainer] "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\BigRigSniX\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
mRun: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WG111v3\WG111v3.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{0A36FA9F-025B-43FF-B111-844E2819EAE7} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{0A36FA9F-025B-43FF-B111-844E2819EAE7}\2456C6C616 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{8A4951DE-0630-4E71-B854-F8426D04158F} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{8A4951DE-0630-4E71-B854-F8426D04158F}\2456C6C616 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{DD21F10D-FD42-42F5-B433-BEDA102DF725} : DHCPNameServer = 192.168.2.1
SSODL: WebCheck - <orphaned>
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\BigRigSniX\AppData\Roaming\Mozilla\Firefox\Profiles\ilarsl5z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&CUI=UN20905905113335195&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - InternetHelper3.1 Customized Web Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&SearchSource=2&CUI=UN20905905113335195&UM=2&q=
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Users\BigRigSniX\AppData\Roaming\Mozilla\Firefox\Profiles\ilarsl5z.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-10-09 23:32; LogMeInClient@logmein.com; C:\Users\BigRigSniX\AppData\Roaming\Mozilla\Firefox\Profiles\ilarsl5z.default\extensions\LogMeInClient@logmein.com
FF - ExtSQL: 2013-10-25 15:36; {07cbf788-1359-421b-a4e3-5a8d041b90a3}; C:\Users\BigRigSniX\AppData\Roaming\Mozilla\Firefox\Profiles\ilarsl5z.default\extensions\{07cbf788-1359-421b-a4e3-5a8d041b90a3}
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2013-10-3 82560]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2013-10-3 42624]
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-9-2 192824]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-9-2 294712]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-8-20 123704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-9-8 31544]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2013-10-3 22680]
R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2013-9-25 148792]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-9-2 241464]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-9-2 212280]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-8-1 251192]
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;C:\Windows\System32\drivers\RtlProt.sys [2007-4-23 31016]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-6 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 AODDriver4.2;AODDriver4.2;C:\Program Files (x86)\GIGABYTE\ET6\amd64\aoddriver2.sys [2012-9-24 57512]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [2013-10-3 3538480]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2013-9-25 301152]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-10-25 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-10-25 701512]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-9-12 414496]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2013-10-3 46136]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2013-10-3 65152]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2013-10-3 88832]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-10-25 25928]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-10-3 565352]
R3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;C:\Windows\System32\drivers\wg111v3.sys [2013-10-10 446976]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-10-3 56448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2013-10-3 30528]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-10-3 160256]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-10-3 1255736]
.
=============== Created Last 30 ================
.
2013-10-25 22:50:14 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\Malwarebytes
2013-10-25 22:50:05 -------- d-----w- C:\ProgramData\Malwarebytes
2013-10-25 22:50:04 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-10-25 22:50:04 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-25 22:36:28 -------- d-----w- C:\Program Files (x86)\Conduit
2013-10-25 22:36:27 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Conduit
2013-10-25 22:36:27 -------- d-----w- C:\ProgramData\Conduit
2013-10-25 22:36:27 -------- d-----w- C:\Program Files (x86)\InternetHelper3.1
2013-10-25 22:36:09 -------- d-----w- C:\Program Files (x86)\SearchProtect
2013-10-25 22:36:06 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\SearchProtect
2013-10-23 23:21:42 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Programs
2013-10-23 19:25:02 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Diagnostics
2013-10-23 10:34:01 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\The Witcher 2
2013-10-23 08:04:36 -------- d-----w- C:\Program Files\CPUID
2013-10-23 07:03:41 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\GameFly
2013-10-23 06:23:45 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\GameFly
2013-10-23 06:23:21 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Deployment
2013-10-23 06:23:21 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Apps
2013-10-13 18:35:32 308736 ----a-w- C:\Windows\System32\ssleay32.dll
2013-10-13 18:35:32 1503744 ----a-w- C:\Windows\System32\libeay32.dll
2013-10-10 21:04:27 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Spotify
2013-10-10 21:04:05 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\Spotify
2013-10-10 19:47:13 -------- d-----w- C:\OEMSettings
2013-10-10 19:46:22 446976 ----a-w- C:\Windows\System32\drivers\wg111v3.sys
2013-10-10 06:53:13 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\LogMeIn
2013-10-10 06:53:13 -------- d-----w- C:\ProgramData\LogMeIn
2013-10-09 00:16:53 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Microsoft Games
2013-10-04 17:52:10 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-10-04 17:52:10 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-10-04 02:44:27 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2013-10-04 02:44:27 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-10-04 02:43:25 -------- d-----w- C:\Windows\SysWow64\Wat
2013-10-04 02:43:25 -------- d-----w- C:\Windows\System32\Wat
2013-10-03 09:23:01 -------- d-----w- C:\Program Files (x86)\NETGEAR
2013-10-03 09:22:40 -------- d-----w- C:\Windows\Downloaded Installations
2013-10-03 08:53:09 -------- d-----w- C:\NVIDIA
2013-10-03 08:51:47 -------- d-----w- C:\Windows\System32\MRT
2013-10-03 08:50:17 -------- d-----w- C:\ProgramData\Oracle
2013-10-03 08:50:13 868264 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-10-03 08:50:13 790440 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-10-03 08:50:11 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-03 08:47:29 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2013-10-03 08:47:18 920864 ----a-w- C:\Windows\System32\nvvsvc.exe
2013-10-03 08:47:18 6599968 ----a-w- C:\Windows\System32\nvcpl.dll
2013-10-03 08:47:18 63776 ----a-w- C:\Windows\System32\nvshext.dll
2013-10-03 08:47:18 3452192 ----a-w- C:\Windows\System32\nvsvc64.dll
2013-10-03 08:47:18 2558240 ----a-w- C:\Windows\System32\nvsvcr.dll
2013-10-03 08:47:18 219424 ----a-w- C:\Windows\System32\nvmctray.dll
2013-10-03 08:47:01 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2013-10-03 08:46:57 -------- d-----w- C:\Program Files\NVIDIA Corporation
2013-10-03 08:31:53 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Macromedia
2013-10-03 08:31:23 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-03 08:31:23 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-10-03 08:30:41 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Adobe
2013-10-03 08:28:10 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-10-03 08:28:10 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-10-03 08:28:10 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-10-03 08:28:10 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-10-03 08:28:10 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-10-03 08:23:51 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2013-10-03 08:22:18 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-10-03 08:22:18 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-10-03 08:22:18 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-10-03 08:20:34 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-10-03 08:20:33 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-10-03 08:20:31 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-10-03 08:20:31 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-10-03 08:14:46 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\AVG2014
2013-10-03 08:14:29 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\TuneUp Software
2013-10-03 08:14:26 -------- d--h--w- C:\$AVG
2013-10-03 08:14:26 -------- d-----w- C:\ProgramData\AVG2014
2013-10-03 08:14:16 -------- d-----w- C:\Program Files (x86)\AVG
2013-10-03 08:11:13 -------- d--h--w- C:\ProgramData\Common Files
2013-10-03 08:11:13 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\MFAData
2013-10-03 08:11:13 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Avg2014
2013-10-03 08:11:13 -------- d-----w- C:\ProgramData\MFAData
2013-10-03 08:05:59 30528 ----a-w- C:\Windows\GVTDrv64.sys
2013-10-03 08:05:51 25640 ----a-w- C:\Windows\gdrv.sys
2013-10-03 08:03:17 -------- d-----w- C:\Intel
2013-10-03 08:03:16 -------- d-----w- C:\Program Files (x86)\AMD
2013-10-03 07:57:08 31272 ----a-w- C:\Windows\System32\AppleChargerSrv.exe
2013-10-03 07:57:08 22680 ----a-w- C:\Windows\System32\drivers\AppleCharger.sys
2013-10-03 07:57:08 -------- d-----w- C:\Program Files\GIGABYTE
2013-10-03 07:57:08 -------- d-----w- C:\Program Files (x86)\GIGABYTE
2013-10-03 07:57:02 753664 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-10-03 07:57:02 69714 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-10-03 07:57:02 63488 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-10-03 07:57:02 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-10-03 07:57:02 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-10-03 07:57:02 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-10-03 07:57:02 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-10-03 07:57:02 184320 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-10-03 07:56:52 88832 ----a-w- C:\Windows\System32\drivers\EtronXHCI.sys
2013-10-03 07:56:52 65152 ----a-w- C:\Windows\System32\drivers\EtronHub3.sys
2013-10-03 07:56:51 -------- d-----w- C:\Program Files (x86)\Etron Technology
2013-10-03 07:55:35 -------- d-----w- C:\Program Files (x86)\AMD APP
2013-10-03 07:55:28 56448 ----a-r- C:\Windows\System32\drivers\usbfilter.sys
2013-10-03 07:55:00 46136 ----a-w- C:\Windows\System32\drivers\amdiox64.sys
2013-10-03 07:55:00 -------- d-----w- C:\ProgramData\AMD
2013-10-03 07:54:59 -------- d-----w- C:\Program Files\ATI Technologies
2013-10-03 07:54:56 82560 ----a-w- C:\Windows\System32\drivers\amd_sata.sys
2013-10-03 07:54:56 42624 ----a-w- C:\Windows\System32\drivers\amd_xata.sys
2013-10-03 07:54:55 -------- d-----w- C:\Program Files\ATI
2013-10-03 07:54:53 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2013-10-03 07:53:36 -------- d-----w- C:\Program Files (x86)\Marvell
2013-10-03 07:53:12 -------- d-----w- C:\Program Files (x86)\Dolby Home Theater v4
2013-10-03 07:53:11 -------- d-sh--w- C:\Windows\Installer
2013-10-03 07:51:56 75024 ----a-w- C:\Windows\System32\R4EEG64A.dll
2013-10-02 10:11:07 -------- d-----w- C:\Windows\Panther
2013-09-26 04:07:30 148792 ----a-w- C:\Windows\System32\drivers\avgdiska.sys
.
==================== Find3M ====================
.
2013-09-22 23:28:06 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-09-22 23:27:49 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-09-22 23:27:48 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-09-22 23:27:48 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-09-22 22:55:10 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-09-22 22:54:51 3959296 ----a-w- C:\Windows\System32\jscript9.dll
2013-09-22 22:54:50 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-09-22 22:54:50 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-09-21 03:38:39 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-09-21 03:30:24 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-09-21 02:48:36 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-09-21 02:39:47 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-09-12 08:17:50 571168 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2013-09-09 05:11:42 31544 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
2013-09-02 17:59:14 212280 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
2013-09-02 17:29:18 294712 ----a-w- C:\Windows\System32\drivers\avgloga.sys
2013-09-02 17:26:50 192824 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
2013-09-02 17:26:42 241464 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
2013-08-28 01:21:06 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-08-21 05:53:58 123704 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
2013-08-02 02:23:53 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-08-02 02:15:44 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-08-02 02:15:03 362496 ----a-w- C:\Windows\System32\wow64win.dll
2013-08-02 02:15:03 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-08-02 02:15:03 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2013-08-02 02:14:57 215040 ----a-w- C:\Windows\System32\winsrv.dll
2013-08-02 02:14:11 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2013-08-02 02:13:34 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2013-08-02 01:59:30 3968960 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-08-02 01:59:30 3913664 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-08-02 01:51:23 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-08-02 01:50:42 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-08-02 01:50:42 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2013-08-02 01:09:17 338432 ----a-w- C:\Windows\System32\conhost.exe
2013-08-02 00:59:09 112640 ----a-w- C:\Windows\System32\smss.exe
2013-08-02 00:45:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-08-02 00:45:36 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-08-02 00:45:35 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-08-02 00:45:34 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-08-02 00:43:05 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-08-01 23:07:06 251192 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2013-08-01 12:09:36 983488 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
.
============= FINISH: 16:00:41.82 ===============
www.malwarebytes.org
Database version: v2013.10.25.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
BigRigSniX :: BIGRIGSNIX-PC [administrator]
Protection: Enabled
10/25/2013 3:51:23 PM
mbam-log-2013-10-25 (15-51-23).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 224965
Time elapsed: 2 minute(s), 11 second(s)
Memory Processes Detected: 2
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (PUP.Optional.Conduit.A) -> 2052 -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\cltmng.exe (PUP.Optional.Conduit.A) -> 3240 -> Delete on reboot.
Memory Modules Detected: 3
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\ChromeModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
Registry Keys Detected: 5
HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\SEARCHPROTECT (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IECT3289663 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
Registry Values Detected: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SearchProtect (PUP.Optional.Conduit.A) -> Data: C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\cltmng.exe -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SearchProtectAll (PUP.Optional.Conduit.A) -> Data: C:\Program Files (x86)\SearchProtect\bin\cltmng.exe -> Quarantined and deleted successfully.
HKCU\Software\SearchProtect|IELastInstalledTBHomepage (PUP.Optional.SearchProtect.A) -> Data: http://search.conduit.com?SearchSource=10&CUI=UN39219230022248310&UM=2&ctid=CT3289663 -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit.A) -> Bad: (http://search.conduit.com/?ctid=CT3...M=2&UP=SP2FE50E72-DFCD-46F2-A4E1-56A3C2564727) Good: (http://www.google.com) -> Quarantined and repaired successfully.
Folders Detected: 28
C:\Program Files (x86)\SearchProtect\bin (PUP.Optional.SearchProtect.A) -> Delete on reboot.
C:\Program Files (x86)\SearchProtect\Dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\ffprotect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi\defaults (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi\defaults\preferences (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE\CT3289663 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
Files Detected: 112
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\cltmng.exe (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\ChromeModule.dll (PUP.Optional.Conduit.A) -> Delete on reboot.
C:\Program Files (x86)\SearchProtect\bin\cltmng.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\SPHook32.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\SPHook64.dll (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\SPRunner.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\bin\SPTool64.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\air4F27.exe (PUP.Optional.SevereWeatherAlerts) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\BTXHcyOu.exe.part (PUP.Optional.InstallCore) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\nsl3B4C.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\nsq435A.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\nsw2724.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\nswED3D.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\WfATYKZ7.exe.part (PUP.Optional.AirInstaller) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\ctbe.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\ffLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\ieLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\spff.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\statisticsStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\stub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Downloads\Setup(1).exe (PUP.Optional.AirInstaller) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Conduit\CT3289663\InternetHelper3.1AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\D7XD0ZI1\internethelper3.1[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\D7XD0ZI1\InternetHelper3.1[2].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\LNG6CX1D\checktbexist[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\LUYRM7IH\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\LUYRM7IH\stublogic[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\LUYRM7IH\swa1_23[1].exe (PUP.Optional.SevereWeatherAlerts) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\Local Settings\Temporary Internet Files\Content.IE5\WIC72A6Y\statisticsstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\FirefoxModule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\ChromeModule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\InternetExplorerModule.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\SPHook32.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\SPHook64.dll (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\SPRunner.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\SPTool64.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\bin\uninstall.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\dialogsApi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\ffprotect\nsprotector.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\ffprotect\abstraction.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SearchProtect\ffprotect\application.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\dialogsApi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\nsprotector.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\abstraction.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\application.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\popupTransparent.xul (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\dialogsApi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository\EN (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository\searchProtectorData (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\chromeid.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\conduit.xml (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\CT3289663.xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\setup.ini.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\version.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi\install.rdf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\BigRigSniX\AppData\Local\Temp\ct3289663\xpi\defaults\preferences\defaults.js (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE\CT3289663\configutaion.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE\CT3289663\SetupIcon.ico (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\ProgramData\Conduit\IE\CT3289663\UninstallerUI.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
(end)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16720 BrowserJavaVersion: 10.40.2
Run by BigRigSniX at 16:00:28 on 2013-10-25
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.16345.14174 [GMT -7:00]
.
AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2014\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Users\BigRigSniX\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uURLSearchHooks: InternetHelper3.1 Toolbar: {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files (x86)\InternetHelper3.1\prxtbInte.dll
mURLSearchHooks: InternetHelper3.1 Toolbar: {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files (x86)\InternetHelper3.1\prxtbInte.dll
mWinlogon: Userinit = userinit.exe,
BHO: InternetHelper3.1 Toolbar: {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files (x86)\InternetHelper3.1\prxtbInte.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: InternetHelper3.1 Toolbar: {07cbf788-1359-421b-a4e3-5a8d041b90a3} - C:\Program Files (x86)\InternetHelper3.1\prxtbInte.dll
uRun: [Spotify Web Helper] "C:\Users\BigRigSniX\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [BackgroundContainer] "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\BigRigSniX\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
mRun: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WG111v3\WG111v3.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{0A36FA9F-025B-43FF-B111-844E2819EAE7} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{0A36FA9F-025B-43FF-B111-844E2819EAE7}\2456C6C616 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{8A4951DE-0630-4E71-B854-F8426D04158F} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{8A4951DE-0630-4E71-B854-F8426D04158F}\2456C6C616 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{DD21F10D-FD42-42F5-B433-BEDA102DF725} : DHCPNameServer = 192.168.2.1
SSODL: WebCheck - <orphaned>
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\BigRigSniX\AppData\Roaming\Mozilla\Firefox\Profiles\ilarsl5z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&CUI=UN20905905113335195&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - InternetHelper3.1 Customized Web Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289663&SearchSource=2&CUI=UN20905905113335195&UM=2&q=
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Users\BigRigSniX\AppData\Roaming\Mozilla\Firefox\Profiles\ilarsl5z.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-10-09 23:32; LogMeInClient@logmein.com; C:\Users\BigRigSniX\AppData\Roaming\Mozilla\Firefox\Profiles\ilarsl5z.default\extensions\LogMeInClient@logmein.com
FF - ExtSQL: 2013-10-25 15:36; {07cbf788-1359-421b-a4e3-5a8d041b90a3}; C:\Users\BigRigSniX\AppData\Roaming\Mozilla\Firefox\Profiles\ilarsl5z.default\extensions\{07cbf788-1359-421b-a4e3-5a8d041b90a3}
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2013-10-3 82560]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2013-10-3 42624]
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-9-2 192824]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-9-2 294712]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-8-20 123704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-9-8 31544]
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2013-10-3 22680]
R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2013-9-25 148792]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-9-2 241464]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-9-2 212280]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-8-1 251192]
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;C:\Windows\System32\drivers\RtlProt.sys [2007-4-23 31016]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-6 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 AODDriver4.2;AODDriver4.2;C:\Program Files (x86)\GIGABYTE\ET6\amd64\aoddriver2.sys [2012-9-24 57512]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [2013-10-3 3538480]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2013-9-25 301152]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-10-25 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-10-25 701512]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-9-12 414496]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2013-10-3 46136]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\System32\drivers\EtronHub3.sys [2013-10-3 65152]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\System32\drivers\EtronXHCI.sys [2013-10-3 88832]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-10-25 25928]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-10-3 565352]
R3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;C:\Windows\System32\drivers\wg111v3.sys [2013-10-10 446976]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-10-3 56448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2013-10-3 30528]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-10-3 160256]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-10-3 1255736]
.
=============== Created Last 30 ================
.
2013-10-25 22:50:14 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\Malwarebytes
2013-10-25 22:50:05 -------- d-----w- C:\ProgramData\Malwarebytes
2013-10-25 22:50:04 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-10-25 22:50:04 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-25 22:36:28 -------- d-----w- C:\Program Files (x86)\Conduit
2013-10-25 22:36:27 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Conduit
2013-10-25 22:36:27 -------- d-----w- C:\ProgramData\Conduit
2013-10-25 22:36:27 -------- d-----w- C:\Program Files (x86)\InternetHelper3.1
2013-10-25 22:36:09 -------- d-----w- C:\Program Files (x86)\SearchProtect
2013-10-25 22:36:06 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\SearchProtect
2013-10-23 23:21:42 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Programs
2013-10-23 19:25:02 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Diagnostics
2013-10-23 10:34:01 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\The Witcher 2
2013-10-23 08:04:36 -------- d-----w- C:\Program Files\CPUID
2013-10-23 07:03:41 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\GameFly
2013-10-23 06:23:45 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\GameFly
2013-10-23 06:23:21 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Deployment
2013-10-23 06:23:21 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Apps
2013-10-13 18:35:32 308736 ----a-w- C:\Windows\System32\ssleay32.dll
2013-10-13 18:35:32 1503744 ----a-w- C:\Windows\System32\libeay32.dll
2013-10-10 21:04:27 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Spotify
2013-10-10 21:04:05 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\Spotify
2013-10-10 19:47:13 -------- d-----w- C:\OEMSettings
2013-10-10 19:46:22 446976 ----a-w- C:\Windows\System32\drivers\wg111v3.sys
2013-10-10 06:53:13 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\LogMeIn
2013-10-10 06:53:13 -------- d-----w- C:\ProgramData\LogMeIn
2013-10-09 00:16:53 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Microsoft Games
2013-10-04 17:52:10 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-10-04 17:52:10 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-10-04 02:44:27 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2013-10-04 02:44:27 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-10-04 02:43:25 -------- d-----w- C:\Windows\SysWow64\Wat
2013-10-04 02:43:25 -------- d-----w- C:\Windows\System32\Wat
2013-10-03 09:23:01 -------- d-----w- C:\Program Files (x86)\NETGEAR
2013-10-03 09:22:40 -------- d-----w- C:\Windows\Downloaded Installations
2013-10-03 08:53:09 -------- d-----w- C:\NVIDIA
2013-10-03 08:51:47 -------- d-----w- C:\Windows\System32\MRT
2013-10-03 08:50:17 -------- d-----w- C:\ProgramData\Oracle
2013-10-03 08:50:13 868264 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-10-03 08:50:13 790440 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-10-03 08:50:11 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-03 08:47:29 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2013-10-03 08:47:18 920864 ----a-w- C:\Windows\System32\nvvsvc.exe
2013-10-03 08:47:18 6599968 ----a-w- C:\Windows\System32\nvcpl.dll
2013-10-03 08:47:18 63776 ----a-w- C:\Windows\System32\nvshext.dll
2013-10-03 08:47:18 3452192 ----a-w- C:\Windows\System32\nvsvc64.dll
2013-10-03 08:47:18 2558240 ----a-w- C:\Windows\System32\nvsvcr.dll
2013-10-03 08:47:18 219424 ----a-w- C:\Windows\System32\nvmctray.dll
2013-10-03 08:47:01 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2013-10-03 08:46:57 -------- d-----w- C:\Program Files\NVIDIA Corporation
2013-10-03 08:31:53 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Macromedia
2013-10-03 08:31:23 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-03 08:31:23 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-10-03 08:30:41 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Adobe
2013-10-03 08:28:10 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-10-03 08:28:10 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-10-03 08:28:10 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-10-03 08:28:10 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-10-03 08:28:10 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-10-03 08:23:51 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2013-10-03 08:22:18 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-10-03 08:22:18 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-10-03 08:22:18 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-10-03 08:20:34 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-10-03 08:20:33 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-10-03 08:20:31 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-10-03 08:20:31 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-10-03 08:14:46 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\AVG2014
2013-10-03 08:14:29 -------- d-----w- C:\Users\BigRigSniX\AppData\Roaming\TuneUp Software
2013-10-03 08:14:26 -------- d--h--w- C:\$AVG
2013-10-03 08:14:26 -------- d-----w- C:\ProgramData\AVG2014
2013-10-03 08:14:16 -------- d-----w- C:\Program Files (x86)\AVG
2013-10-03 08:11:13 -------- d--h--w- C:\ProgramData\Common Files
2013-10-03 08:11:13 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\MFAData
2013-10-03 08:11:13 -------- d-----w- C:\Users\BigRigSniX\AppData\Local\Avg2014
2013-10-03 08:11:13 -------- d-----w- C:\ProgramData\MFAData
2013-10-03 08:05:59 30528 ----a-w- C:\Windows\GVTDrv64.sys
2013-10-03 08:05:51 25640 ----a-w- C:\Windows\gdrv.sys
2013-10-03 08:03:17 -------- d-----w- C:\Intel
2013-10-03 08:03:16 -------- d-----w- C:\Program Files (x86)\AMD
2013-10-03 07:57:08 31272 ----a-w- C:\Windows\System32\AppleChargerSrv.exe
2013-10-03 07:57:08 22680 ----a-w- C:\Windows\System32\drivers\AppleCharger.sys
2013-10-03 07:57:08 -------- d-----w- C:\Program Files\GIGABYTE
2013-10-03 07:57:08 -------- d-----w- C:\Program Files (x86)\GIGABYTE
2013-10-03 07:57:02 753664 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-10-03 07:57:02 69714 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-10-03 07:57:02 63488 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-10-03 07:57:02 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-10-03 07:57:02 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-10-03 07:57:02 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-10-03 07:57:02 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-10-03 07:57:02 184320 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-10-03 07:56:52 88832 ----a-w- C:\Windows\System32\drivers\EtronXHCI.sys
2013-10-03 07:56:52 65152 ----a-w- C:\Windows\System32\drivers\EtronHub3.sys
2013-10-03 07:56:51 -------- d-----w- C:\Program Files (x86)\Etron Technology
2013-10-03 07:55:35 -------- d-----w- C:\Program Files (x86)\AMD APP
2013-10-03 07:55:28 56448 ----a-r- C:\Windows\System32\drivers\usbfilter.sys
2013-10-03 07:55:00 46136 ----a-w- C:\Windows\System32\drivers\amdiox64.sys
2013-10-03 07:55:00 -------- d-----w- C:\ProgramData\AMD
2013-10-03 07:54:59 -------- d-----w- C:\Program Files\ATI Technologies
2013-10-03 07:54:56 82560 ----a-w- C:\Windows\System32\drivers\amd_sata.sys
2013-10-03 07:54:56 42624 ----a-w- C:\Windows\System32\drivers\amd_xata.sys
2013-10-03 07:54:55 -------- d-----w- C:\Program Files\ATI
2013-10-03 07:54:53 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2013-10-03 07:53:36 -------- d-----w- C:\Program Files (x86)\Marvell
2013-10-03 07:53:12 -------- d-----w- C:\Program Files (x86)\Dolby Home Theater v4
2013-10-03 07:53:11 -------- d-sh--w- C:\Windows\Installer
2013-10-03 07:51:56 75024 ----a-w- C:\Windows\System32\R4EEG64A.dll
2013-10-02 10:11:07 -------- d-----w- C:\Windows\Panther
2013-09-26 04:07:30 148792 ----a-w- C:\Windows\System32\drivers\avgdiska.sys
.
==================== Find3M ====================
.
2013-09-22 23:28:06 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-09-22 23:27:49 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-09-22 23:27:48 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-09-22 23:27:48 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-09-22 22:55:10 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-09-22 22:54:51 3959296 ----a-w- C:\Windows\System32\jscript9.dll
2013-09-22 22:54:50 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-09-22 22:54:50 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-09-21 03:38:39 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-09-21 03:30:24 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-09-21 02:48:36 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-09-21 02:39:47 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-09-12 08:17:50 571168 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2013-09-09 05:11:42 31544 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
2013-09-02 17:59:14 212280 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
2013-09-02 17:29:18 294712 ----a-w- C:\Windows\System32\drivers\avgloga.sys
2013-09-02 17:26:50 192824 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
2013-09-02 17:26:42 241464 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
2013-08-28 01:21:06 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-08-21 05:53:58 123704 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
2013-08-02 02:23:53 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-08-02 02:15:44 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-08-02 02:15:03 362496 ----a-w- C:\Windows\System32\wow64win.dll
2013-08-02 02:15:03 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-08-02 02:15:03 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2013-08-02 02:14:57 215040 ----a-w- C:\Windows\System32\winsrv.dll
2013-08-02 02:14:11 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2013-08-02 02:13:34 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2013-08-02 01:59:30 3968960 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-08-02 01:59:30 3913664 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-08-02 01:51:23 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-08-02 01:50:42 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-08-02 01:50:42 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2013-08-02 01:09:17 338432 ----a-w- C:\Windows\System32\conhost.exe
2013-08-02 00:59:09 112640 ----a-w- C:\Windows\System32\smss.exe
2013-08-02 00:45:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-08-02 00:45:36 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-08-02 00:45:35 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-08-02 00:45:34 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-08-02 00:43:05 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-08-01 23:07:06 251192 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2013-08-01 12:09:36 983488 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
.
============= FINISH: 16:00:41.82 ===============